Worm

Should I remove “Worm:Win32/Vobfus.IJ”?

Malware Removal

The Worm:Win32/Vobfus.IJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.IJ?


File Info:

name: E1F1A3721CB22E1E1395.mlw
path: /opt/CAPEv2/storage/binaries/418aad9c49621fd162dc07ae0254ad4e56c23975dd4c357d4d1ae4a644a40dd8
crc32: 142407FB
md5: e1f1a3721cb22e1e1395c3c2bb577bac
sha1: 02f6ad8120f2e0ca94d0c1a38a5bd72c5d51edbf
sha256: 418aad9c49621fd162dc07ae0254ad4e56c23975dd4c357d4d1ae4a644a40dd8
sha512: fc06275c0c8f4a2500069e45c430a4aa364440a07bfc73b4693c8b2c0cd879f77383e9b552dd2d1ec1e184b415fdf358f5f27e7259a23545569b213396e588c3
ssdeep: 1536:tXQ8p3DBeZUBFTgVjtXZTto1e9uCLBCPr8/NL44PerV5I8kIi/2O:dbpteZU7TgdTq1ZrJO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9C3D53FBA569465E519293029F7C7F616BB6C1A2E0B505B6B0037BA4CB3F000C9DE67
sha3_384: 82f5a2bd1141867267900d016d59b9dce39ad598fa3d987174be5bffea925bbd990667d208faf281bfea7408a97de074
ep_bytes: 689c134000e8eeffffff000000000000
timestamp: 2012-09-25 06:23:42

Version Info:

0: [No Data]

Worm:Win32/Vobfus.IJ also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Barys.431081
CAT-QuickHealWorm.VobfusMF.S28101913
SkyhighBehavesLike.Win32.Generic.ct
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.431081
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.21cb22
BaiduWin32.Worm.Pronny.ew
VirITTrojan.Win32.Generic.GIZ
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.FO
APEXMalicious
ClamAVWin.Trojan.VB-1720
KasperskyWorm.Win32.Vobfus.agxr
BitDefenderGen:Variant.Barys.431081
NANO-AntivirusTrojan.Win32.Autoruner.cinaru
AvastWin32:VB-AEOA [Trj]
TencentWorm.Win32.Vobfus.ky
EmsisoftGen:Variant.Barys.431081 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.26616
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e1f1a3721cb22e1e
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
VaristW32/VB.HD.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.IJ
XcitiumWorm.Win32.VB.IVZ@4rktsd
ArcabitTrojan.Barys.D693E9
ViRobotWorm.Win32.A.Vobfus.118784
ZoneAlarmWorm.Win32.Vobfus.agxr
GDataWin32.Trojan.PSE.56P7T0
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R37786
VBA32Worm.Vobfus
ALYacGen:Variant.Barys.431081
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!fYvWsAMx25M
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.11612875.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36802.hmX@aeBxWJf
AVGWin32:VB-AEOA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/VBCode.BFM

How to remove Worm:Win32/Vobfus.IJ?

Worm:Win32/Vobfus.IJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment